178.73.192.18

Classification: Suspicious

178.73.192.18 is a suspicious IP address. Linked to Darktortilla malware. Reported by 5 threat sources, last seen 2026-08-01. Network: AS42708 Frootynet.

MITRE ATT&CK associations

Malware families: DARKTORTILLA (S1066)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2025-08-28 15:01:45 2026-08-01 15:08:09 anonymization vpn
Mail Spammer Barracuda 2023-12-04 06:40:40 2026-08-01 15:08:09 attacker malicious-activity
DarkTortilla ThreatFox Abuse.ch 2025-06-17 08:18:27 2025-06-19 07:19:00 malicious-activity S1066 DarkTortilla
DDoS attack on site 82.gymnasium.kr.ua Blocklist.net.ua 2023-12-04 06:40:39 2024-12-03 16:40:07 malicious-activity
Mail Spammer Abuseat.org 2023-12-04 06:40:40 2023-12-04 06:40:40

Tags

abuse darktortilla port:7044

Whois information

AS name
AS42708 Frootynet
AS registry
ripencc
AS date
2010-03-22 00:00:00
AS CIDR
178.73.192.0/18
CIDR
178.73.192.0/23
Registrant
Frootynet
Address
Box 6322 102 35 Stockholm Sweden
City
Stockholm
Postal code
101 23
Country
SE — Sweden 🇸🇪
Contact email
[email protected]
First indexed
2023-12-04 06:40:39
Last updated
2026-08-01 15:08:10

Malicious IPs in the same CIDR

178.73.218.12 178.73.218.3 178.73.192.6 178.73.212.20 178.73.218.4